What the Basel Committee Has Actually Said About AI and ML
8 min read · updated August 11, 2026
If somebody tells you a model governance control is required by Basel, ask which document. The Basel Committee on Banking Supervision has published observations on artificial intelligence and machine learning; it has not issued an AI standard, and the difference is the whole of whether the control is enforceable.
Nothing the Committee publishes is law
The Basel Committee is a standard-setting body hosted by the Bank for International Settlements, whose members are central banks and bank supervisors from around thirty jurisdictions. It has no treaty basis and no enforcement power. Its output binds nobody directly; members undertake to implement its standards in their own law and rulebooks, and the Committee runs a Regulatory Consistency Assessment Programme to grade how faithfully they have done so. Even within the Committee’s own output there is a hierarchy: standards that enter the consolidated Basel Framework, guidelines and sound practices that supervisors are expected to reflect, and newsletters, reports and working papers that carry no expectation at all.
What actually exists on AI/ML
The Committee’s dedicated AI material sits at the bottom of that hierarchy. Its newsletter on artificial intelligence and machine learning, published in March 2022, sets out supervisory observations rather than requirements: that banks’ use of AI/ML raises questions about the explainability of models, about governance and accountability where a model is developed outside the traditional model risk function, about data quality and representativeness, and about reliance on third parties for models and data. Its work on the digitalisation of finance, published in 2024, revisits the same ground across a wider set of technologies. The Committee’s publications are listed on the BIS site, and the newsletters are labelled as such on their own front matter.
Read the newsletter for what it signals rather than for rules to implement: it tells you what the supervisors sitting on the Committee were already asking their banks in 2022, which is a reasonable predictor of what your own examiner will ask. It does not give you a control framework, and it does not purport to.
The standards that already reach AI
The Committee’s actual leverage over AI risk runs through instruments that never mention AI. Three matter.
- BCBS 239, the Principles for effective risk data aggregation and risk reporting, published January 2013 and applicable to global systemically important banks. Its principles on data accuracy and integrity, completeness, timeliness and adaptability bear directly on training and feature data, and its governance principle requires the board to be aware of limitations that prevent full aggregation. The text is published by the BIS.
- The revised Principles for the Sound Management of Operational Risk and the Principles for Operational Resilience, both published in March 2021. These bring model failure, ICT dependency and third-party concentration inside the operational risk taxonomy, which is where an inference provider outage or a silent model version change actually lands.
- The supervisory review process in Pillar 2. A supervisor that considers a bank’s AI-driven credit decisioning inadequately controlled does not need an AI rule to act; it can raise a Pillar 2 capital requirement or impose a qualitative measure.
How it becomes binding on you
For a US bank, the operative model-risk document is not from Basel at all. It is SR 11-7, the Federal Reserve and OCC supervisory guidance on model risk management issued in April 2011, which defines a model, sets out the three pillars of development and implementation, validation, and governance, and introduces the concept of effective challenge — critical analysis by objective, informed parties who can compel change. That is the standard an examiner will hold an AI model to, and its awkward fit with a general-purpose foundation model (no development documentation you own, no stable version, no conceptual soundness argument in the usual sense) is a live supervisory problem rather than a solved one.
Third-party model risk runs through the interagency guidance on third-party relationships finalised in June 2023 by the Federal Reserve, FDIC and OCC, which replaced the agencies’ separate bulletins. European banks get the same substance through the EBA guidelines on outsourcing and on internal governance, and increasingly through DORA. None of these is Basel; all of them are how Basel’s observations reach your control environment.
What the Committee has not answered
Three questions are genuinely open at Committee level, and it is more useful to name them than to pretend an answer exists. First, whether a purchased general-purpose model is a “model” for model risk purposes at all, or a vendor service subject to third-party risk rules — the two regimes demand very different evidence, and firms are currently choosing. Second, whether validation can be satisfied by outcome testing alone where conceptual soundness cannot be assessed because the weights and training data are not available. Third, how concentration risk should be measured when a large share of the banking system depends on a handful of model providers, which is a systemic question the Financial Stability Board has raised in its own work on AI in finance and which no capital rule currently captures.
Until those are settled, the defensible position is the boring one: treat an AI system as in scope for model risk management, document why each SR 11-7 element is satisfied or why it cannot be, and record the gap rather than papering it. That is also the position that survives being asked to show your evidence.